Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5193 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.7Linux

High [CVE-2026-4601] Private Key Recovery via Missing Cryptographic Step in DSA Signing

Private Key Recovery via Missing Cryptographic Step in DSA Signing. Red Hat rates this important (CVSS 8.7). Weakness: CWE-325. Affected package(s): migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.

CVE-2026-4601
Unclassified
Mar 23, 2026
High7.5Linux

High [CVE-2026-4598] Denial of Service via infinite loop in bnModInverse function with crafted inputs

Denial of Service via infinite loop in bnModInverse function with crafted inputs. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Affected package(s): quay/quay-rhel8:1779811473, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1779822261, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.

CVE-2026-4598
Unclassified
Mar 23, 2026
High7.5Linux

High [CVE-2026-4602] Signature verification bypass via negative exponent handling

Signature verification bypass via negative exponent handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-681. Affected package(s): migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.

CVE-2026-4602
Unclassified
Mar 23, 2026
High8.2Linux

High [CVE-2026-4600] Cryptographic signature forgery via malicious DSA domain parameters

Cryptographic signature forgery via malicious DSA domain parameters. Red Hat rates this important (CVSS 8.2). Weakness: CWE-347. Affected package(s): migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.

CVE-2026-4600
Unclassified
Mar 23, 2026
High8.8Linux

High [CVE-2026-4680] Use after free in FedCM

Use after free in FedCM. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4680
Unclassified
Mar 23, 2026
Medium6.5Linux

Medium [CVE-2026-33176] Denial of Service via large scientific notation strings

Denial of Service via large scientific notation strings. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected package(s): rubygem-activesupport. Resolved in Red Hat advisory RHSA-2026:14835 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-33176
Unclassified
Mar 23, 2026
Medium5.5Linux

Medium [CVE-2026-26209] Denial of Service due to uncontrolled recursion via crafted CBOR payloads

Denial of Service due to uncontrolled recursion via crafted CBOR payloads. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected package(s): rhaiis/vllm-rocm-rhel9:1779223651, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1779223654, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:19724 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26209
Unclassified
Mar 23, 2026
Medium6.1Linux

Medium [CVE-2026-4647] Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library

Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-4647
Red Hat Enterprise Linux
Mar 23, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-4674] Out of bounds read in CSS

Out of bounds read in CSS. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4674
Unclassified
Mar 23, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-4675] Heap buffer overflow in WebGL

Heap buffer overflow in WebGL. Red Hat rates this important (CVSS 6.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4675
Unclassified
Mar 23, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-4677] Out of bounds read in WebAudio

Out of bounds read in WebAudio. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4677
Unclassified
Mar 23, 2026
Critical9.8Linux

Critical [CVE-2026-33228] Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.

Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-915. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat 3scale API Management Platform 2; Red Hat Build of Keycloak; and 1 more.

CVE-2026-33228
Unclassified
Mar 20, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-33210] Denial of Service or Information Disclosure via format string injection

Denial of Service or Information Disclosure via format string injection. Red Hat rates this important (CVSS 9.1). Weakness: CWE-134. Affected package(s): ruby4.0, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:20606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-33210
Red Hat Enterprise Linux
Mar 20, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-33186] Authorization bypass due to improper HTTP/2 path validation

Authorization bypass due to improper HTTP/2 path validation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-551. Affected package(s): rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1780078429, odf4/odf-csi-addons-sidecar-rhel9:1781550957, rhtas/trillian-logserver-rhel9:1776243434, openshift4/ose-cluster-olm-rhel9-operator:1779787336, rhdh/rhdh-rhel9-operator:1774544220, openshift4/ose-csi-driver-nfs-rhel9:1778242571. Resolved in Red Hat advisory RHSA-2026:27893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat Satellite 6.16 for RHEL 8; and 113 more.

CVE-2026-33186
Red Hat Enterprise LinuxLinux Kernel
Mar 20, 2026
Critical9.1Linux

Critical [CVE-2026-23537] Unauthenticated Arbitrary File Write

Unauthenticated Arbitrary File Write. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-862. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23537
Unclassified
Mar 20, 2026
High8.1Linux

High [CVE-2026-33236] Arbitrary file overwrite and creation via path traversal in XML index files

Arbitrary file overwrite and creation via path traversal in XML index files. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1776319185, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1776243238, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1778262893. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more.

CVE-2026-33236
Unclassified
Mar 20, 2026
High7.5Linux

High [CVE-2026-33231] Denial of Service via unauthenticated remote shutdown

Denial of Service via unauthenticated remote shutdown. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1780069222, rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1780069226, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1778262893. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more.

CVE-2026-33231
Unclassified
Mar 20, 2026
High8.2Linux

High [CVE-2026-33180] Information disclosure and potential impersonation via HTTP redirects sending sensitive headers

Information disclosure and potential impersonation via HTTP redirects sending sensitive headers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-201. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2026-33180
Unclassified
Mar 20, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-33154] Arbitrary code execution via Server-Side Template Injection

Arbitrary code execution via Server-Side Template Injection. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-917. Affected package(s): ansible-automation-platform, automation-controller. Resolved in Red Hat advisory RHSA-2026:34160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-33154
Unclassified
Mar 20, 2026
High7.8Linux

High [CVE-2026-33150] Arbitrary code execution via use-after-free in io_uring subsystem

Arbitrary code execution via use-after-free in io_uring subsystem. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-33150
Red Hat Enterprise Linux
Mar 20, 2026

← All vendors